One visibility rule for every public read

VisibilityPolicy.IsPublic is the single expression for "anyone may see
this" (Public or Unlisted, not deleted); the outbox, the object and
activity endpoints, the HTML pages and NodeInfo all use it instead of
spelling it out. CanSee answers for a persona: the author, a mentioned
local persona, a conversation member for Direct, a circle member for
Circle; followers-only waits for P1.2's follows.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_012CzABvBkbcFqoHdmi8b9WB
This commit is contained in:
thepraandClaude Opus 5.5 committed 2026-10-01 11:26:51 +02:00
1 parent 5a13597c00
commit 1c78da34a9
5 files changed
+97 -15

No files matched your search

@@ -0,0 +1,42 @@
using MongoDB.Entities;
using PrivaPub.Models.Group;
using PrivaPub.Models.Post;
using System.Linq.Expressions;
using GroupEntity = PrivaPub.Models.Group.Group;
namespace PrivaPub.Domain.Privacy
{
public static class VisibilityPolicy
{
public static readonly Expression<Func<Post, bool>> IsPublic = p =>
!p.DeletedAt.HasValue && (p.Visibility == PostVisibility.Public || p.Visibility == PostVisibility.Unlisted);
static readonly Func<Post, bool> IsPublicCompiled = IsPublic.Compile();
public static async Task<bool> CanSee(Post post, string viewerAvatarId, CancellationToken token)
{
if (post == default || post.DeletedAt.HasValue)
return false;
if (IsPublicCompiled(post))
return true;
if (string.IsNullOrEmpty(viewerAvatarId))
return false;
if (post.GroupUserId == viewerAvatarId || post.Mentions.Any(m => m.IsLocal && m.AccountId == viewerAvatarId))
return true;
return post.Visibility switch
{
PostVisibility.Direct => !string.IsNullOrEmpty(post.ConversationId) && await DB.Default.Find<DmGroup>()
.Match(g => g.ID == post.ConversationId && g.Members.Any(m => !m.IsForeign && m.AvatarId == viewerAvatarId))
.ExecuteAnyAsync(token),
PostVisibility.Circle => !string.IsNullOrEmpty(post.GroupId) && await DB.Default.Find<GroupEntity>()
.Match(g => g.ID == post.GroupId && g.Members.Any(m => !m.IsForeign && m.AvatarId == viewerAvatarId))
.ExecuteAnyAsync(token),
_ => false
};
}
}
}